1. Reporting a vulnerability
If you believe you have found a security vulnerability affecting Grand Bounce, email the details privately to jay@grandbounce.com. Please do not publish the vulnerability before Grand Bounce has had a reasonable opportunity to investigate and address it.
When possible, include the following information:
- A description of the issue and its potential impact.
- The affected page, feature, account flow, or service.
- Clear reproduction steps or a limited proof of concept.
- Any remediation you recommend.
2. Responsible testing
- Only test accounts and data you own or have explicit permission to use.
- Do not access, change, retain, or disclose another person's information.
- Avoid service disruption, denial-of-service testing, spam, social engineering, and destructive activity.
- Stop testing and report the issue immediately if you encounter sensitive information.
3. What to expect
Grand Bounce will review reports, may request additional information, and will coordinate remediation and responsible disclosure when appropriate. Grand Bounce does not currently operate a paid bug bounty program.
The machine-readable security contact is available at /.well-known/security.txt.